CVE-2021-31818
Summary
| CVE | CVE-2021-31818 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-17 14:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2021-04 - SQL Injection in the Events REST API (CVE-2021-31818) | advisories.octopus.com | ||
| 2021-04 - SQL Injection in the Events REST API (CVE-2021-31818) | MISC | advisories.octopus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.